Skip to main content
VendorsBlack Duck

Black Duck

Cybersecurity reports and statistics published by Black Duck

8 categories6 reports

Recent Statistics & Reports

Mean vulnerabilities per codebase increased by 107% year-over-year.

5/27/2026
VulnerabilitiesOpen Source Security

Open source component counts increased by 30% year-over-year.

5/27/2026
Open SourceDependency ManagementOpen Source Security

68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.

5/27/2026
LicensingOpen SourceOpen Source Security

76% of organizations check AI-generated code for security risks.

5/27/2026
AI-Generated CodeAI RiskOpen Source Security

54% of organizations evaluate AI-generated code for IP and license risks.

5/27/2026
LicensingAI RiskAI-Generated Code

56% of organizations assess quality issues in AI-generated code.

5/27/2026
Software QualityAI RiskAI-Generated Code

The number of files per codebase grew by 74% year-over-year.

5/27/2026
Codebase SizeSoftware CompositionOpen Source Security

24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.

5/27/2026
AI-Generated CodeAI RiskOpen Source Security

98% of codebases contain open source components.

5/27/2026
Open SourceOpen Source Security

Streamlining of responsible vulnerability disclosure grew by more than 40%.

2/9/2026
Vulnerability DisclosureRegulatory ComplianceApplication Security

Nearly 30% more organizations now produce SBOMs to meet transparency requirements.

2/9/2026
SBOMRegulatory Compliance

Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.

2/9/2026
AI SecurityThreat IntelligenceApplication Security

Application of custom rules to automated code review tools to catch issues unique to AI-generated code increased by 10%.

2/9/2026
AI SecurityCode ReviewDeveloper Tools

Organizations delivering expertise through open collaboration channels increased by 29%.

2/9/2026
Collaboration

Use of risk-ranking methods to determine where LLM-generated code is safe to deploy increased by 12%.

2/9/2026
AI SecurityRisk ManagementApplication Security

Establishment of standardized technology stacks rose by more than 40%.

2/9/2026
Technology StackApplication Security

Automated verification of infrastructure security surged by more than 50%.

2/9/2026
Infrastructure SecurityAutomationApplication Security

95% of surveyed organizations reported using AI tools in software development.

1/1/2026
AI ToolsSoftware Development

Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.

1/1/2026
Open SourceSoftware SecurityOpen Source Dependencies

63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.

1/1/2026
Third-Party Software SecuritySoftware Supply ChainSBOM Validation

Showing 1-20 of 51 results